Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Mar 2026, 18:31
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mattermost
Mattermost mattermost Server |
|
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| References | () https://mattermost.com/security-updates - Vendor Advisory |
16 Mar 2026, 14:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 14:19
Updated : 2026-03-18 18:31
NVD link : CVE-2026-2462
Mitre link : CVE-2026-2462
CVE.ORG link : CVE-2026-2462
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-863
Incorrect Authorization
